PT-2024-12678 · Ibm · Ibm Aspera Shares

Published

2024-08-09

·

Updated

2024-11-08

·

CVE-2023-38018

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions IBM Aspera Shares version 1.10.0 PL2
Description The issue arises from the software's failure to invalidate a session after a password change, potentially allowing an authenticated user to impersonate another user on the system. This flaw in user session handling could allow attackers to impersonate any user within the system, posing a substantial security risk.
Recommendations For IBM Aspera Shares version 1.10.0 PL2, consider disabling the user session handling feature until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation. As a temporary workaround, limit the ability of authenticated users to interact with other user accounts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2023-38018

Affected Products

Ibm Aspera Shares